Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Bangladesh
BDschema gdpri-v2trajectory: not yet assessedin transitionoverlaps: AIC
Last updated · 10 categories · 10
claims · 22 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
10Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction lead brief
Standing brief, as of 28 September 2026.
Lead Signal
Bangladesh's data-protection posture has materially advanced with the enactment of the Personal Data Protection Ordinance, 2025, which establishes the National Data Governance Authority as the country's supervisory body and recognises citizens as owners of their own personal data. This is a significant departure from the prior baseline position, which recorded no comprehensive statute and no independent data protection authority operating in Bangladesh. The Ordinance is understood to mandate explicit consent for the collection and processing of personal data and to impose strict rules around sensitive data and cross-border transfers, corroborated across two independent secondary sources. The procedural status of the instrument, however, carries genuine sourcing ambiguity this cycle: one source characterises the operative instrument as the Personal Data Protection Act, 2026 (Law 63 of 2026), understood to have been finalised by Parliament after originating as the 2025 Ordinance, while another source frames it as the Ordinance as amended. This Act-status characterisation has not yet been corroborated by a directly retrieved primary gazette citation.
Other Developments
Data localisation arrives via amendment. The Personal Data Protection (Amendment) Ordinance, 2026, gazetted on 5 February 2026, introduces a requirement that at least one synchronised real-time copy of restricted data or Critical Information Infrastructure data be maintained within Bangladesh's borders, as defined by reference to the Cyber Security Ordinance, 2025. This is a new cross-border constraint layered onto the 2025 Ordinance's original consent and processing framework, corroborated by two independent sources with reasonable specificity.
Penalties softened for corporate managing directors. The same February 2026 Amendment Ordinance modifies Section 48 of the 2025 Ordinance, replacing imprisonment for managing directors of companies found to violate data-subject rights with monetary fines only. This is a material softening of the original penalty regime, again corroborated across independent sources.
State-exemption scope questioned. Legal commentary in The Business Standard characterises the Ordinance's exemptions for state actors as open-ended, arguing they allow the executive to bypass privacy rules under an undefined "public interest" standard that the commentary contends is unconstrained by the narrower privacy guarantee in Constitution Article 43. This governance-risk signal is reported at Uncertain confidence, as it is not yet grounded in specific exemption clause text retrieved this cycle.
Cross-Monitor Connections
The data-localisation and account/wallet-freeze enforcement developments occurring in parallel in Bangladesh's gambling-regulation space this cycle are tracked separately by financial-integrity and advennt; readers following those monitors should note that the same period saw new gambling-related account-freeze powers introduced under a separate statute, distinct from the data-protection developments described here. No cross-domain analysis of that development is offered in this brief.
Outlook
The National Data Governance Authority's enforcement capacity is understood to be phasing in over roughly eighteen months from the Ordinance's gazette date, reaching full operability around the second quarter of 2027. Until then, the practical reach of the Authority's supervisory powers remains only partially resolved even though the underlying statutory obligations are already in force. The unresolved Ordinance-versus-Act procedural status is the most consequential open item: primary-source confirmation from Bangladesh's official law repository would resolve whether the operative instrument is properly characterised as an Act or as an amended Ordinance, and would materially firm up confidence across several of this cycle's claims.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Core regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.
Primary frameworkData Protection Ordinance, 2025 (Bangladesh), read with the National Data Governance and Interoperability Authority Ordinance 2025
Supervisory authorityNational Data Governance Authority
Traffic-light rationale — AmberCore regulator and instrument identity confirmed via secondary reporting; material/territorial scope and registration mechanics unconfirmed.
Sub-modules (5)
Regulator And AuthorityGreen
NDGIA is named as the enforcement and guidance-issuing body for the Ordinance.
Claims (1):
The National Data Governance and Interoperability Authority (NDGIA), established under the National Data Governance and Interoperability Authority Ordinance 2025, is responsible for enforcing Bangladesh's Data Protection Ordinance 2025 and issuing related guidelines.
Act And InstrumentsAmber
Instrument progressed from presidential ordinance to parliamentary enactment within 2026.
Claims (2):
The President of Bangladesh promulgated the Personal Data Protection Ordinance as a presidential ordinance in early-to-mid 2026.
Parliament of Bangladesh subsequently enacted the Personal Data Protection legislation into statute, formalising the framework earlier established by presidential ordinance.
Material ScopeRed
No confirmed definition of covered personal data / processing scope retrieved.
Bangladesh's data protection landscape moved from a decade of draft bills (2022 Draft Data Protection Act, 2023 ICT Department drafts) into a live instrument: the Data Protection Ordinance, 2025. The Ordinance was promulgated by presidential ordinance and, per later reporting, subsequently enacted into statute by Parliament. Supervisory authority sits with the newly created National Data Governance and Interoperability Authority (NDGIA), established under a companion National Data Governance and Interoperability Authority Ordinance 2025. Material scope, territorial scope, and registration/filing obligations could not be confirmed from accessible sources (primary Bangla-language text not independently retrieved; secondary commentary paywalled).
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainDataGuidance — The National Data Governance and Interoperability Authority (NDGIA), established under the National Data Governance and Interoperability Authority Ordinance 2025, is responsible for enforcing Bangladesh's Data Protection Ordinance 2025 and issuing related guidelines.observed
UncertainDataGuidance — The President of Bangladesh promulgated the Personal Data Protection Ordinance as a presidential ordinance in early-to-mid 2026.observed
UncertainDataGuidance — Parliament of Bangladesh subsequently enacted the Personal Data Protection legislation into statute, formalising the framework earlier established by presidential ordinance.observed
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedOnly a generic characterisation of the regime as 'consent-based' is evidenced; no enumerated lawful bases or special-category provisions confirmed.
Sub-modules (4)
Lawful BasesRed
Only a general 'consent-based' characterisation is evidenced; no enumerated Art 6-style lawful basis list confirmed.
Claims (1):
Academic analysis of Bangladesh's data protection framework describes state surveillance powers as operating outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance (PDPO).
Consent ThresholdsRed
No confirmed consent-validity standard (freely given/informed/revocable) retrieved.
Independent academic analysis characterises the Bangladesh Data Protection Ordinance (PDPO) as establishing consent-based and rights-oriented processing mechanisms, but the enumerated lawful bases, consent standards, special-category rules, and pseudonymisation/anonymisation safe harbours could not be independently confirmed from accessible primary text.
no periodic updates on record for this sub-brief
Sources and claims (1)
UncertainarXiv — Academic analysis of Bangladesh's data protection framework describes state surveillance powers as operating outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance (PDPO).observed
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — RedOnly a generic 'rights-oriented' characterisation is evidenced; no enumerated individual rights or deadlines confirmed.
Sub-modules (5)
Access RightRed
General 'rights-oriented' characterisation only; no confirmed access-request mechanism.
Claims (1):
Academic commentary characterises the Data Protection Ordinance (PDPO) as establishing rights-oriented mechanisms for data subjects, distinct from the surveillance powers retained under sectoral telecommunications and cybersecurity law.
Rectification And ErasureRed
No confirmed rectification/erasure right retrieved.
Secondary academic commentary characterises the Ordinance as establishing 'rights-oriented' mechanisms for data subjects, but specific rights (access, rectification/erasure, restriction/objection, portability) and statutory response deadlines could not be confirmed from accessible sources.
Sources and claims (1)
UncertainarXiv — Academic commentary characterises the Data Protection Ordinance (PDPO) as establishing rights-oriented mechanisms for data subjects, distinct from the surveillance powers retained under sectoral telecommunications and cybersecurity law.observed
Breach notification obligation confirmed as within the Ordinance's scope, enforced by NDGIA.
Claims (1):
The Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, with the National Data Governance and Interoperability Authority responsible for enforcement.
Retention And DisposalRed
No confirmed retention-limit or disposal-duty provision retrieved.
Secondary guidance confirms the Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, enforced by the NDGIA. DPIA triggers, DPO appointment thresholds, ROPA requirements, joint-controller rules, detailed security-measure standards, and retention/disposal duties could not be confirmed from accessible sources.
no periodic updates on record for this sub-brief
Sources and claims (1)
UncertainDataGuidance — The Data Protection Ordinance, 2025 applies to data breach notification in Bangladesh, with the National Data Governance and Interoperability Authority responsible for enforcement.observed
No transfer-mechanism detail (adequacy, SCCs, BCRs, derogations), adequacy decisions received or granted, transfer-impact-assessment requirement, or data-localisation mandate could be confirmed for the Data Protection Ordinance, 2025 from accessible sources. Earlier (pre-2025) draft bills reportedly raised cross-border transfer concerns per industry commentary, but underlying text was not independently accessible.
Telecom interception powers confirmed as a sectoral carve-out operating alongside the data protection framework.
Claims (1):
The Bangladesh Telecommunication Regulation Act (Section 97) authorizes telecommunications operators and authorities to intercept and monitor communications, including traffic data and content, on grounds such as national security, public order, and public safety.
Employment DataRed
No confirmed employment-data-specific regime retrieved.
The clearest confirmed sectoral overlay is telecommunications: the Bangladesh Telecommunication Regulation Act empowers interception of communications on national-security/public-order grounds, operating through sectoral law rather than the data protection framework. Financial-sector, health-sector, employment, credit-scoring, education, and insurance overlays could not be confirmed from accessible sources.
Sources and claims (1)
UncertainarXiv — The Bangladesh Telecommunication Regulation Act (Section 97) authorizes telecommunications operators and authorities to intercept and monitor communications, including traffic data and content, on grounds such as national security, public order, and public safety.observed
No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, cross-context-advertising provision, or direct-marketing consent/suppression rule could be confirmed for Bangladesh from accessible sources.
Cyber Security Ordinance 2025 interception powers confirmed as operating outside the Ordinance's consent-based safeguards.
Claims (1):
The Cyber Security Ordinance 2025 permits interception of, or access to, traffic data where authorities have 'reason to believe' that an offense has occurred, is occurring, or may occur, enabling investigative and preventative surveillance activities that operate outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance.
Category narrative59 words
The confirmed finding in this module is a state-surveillance carve-out: the Cyber Security Ordinance 2025 permits interception of, or access to, traffic data on a 'reason to believe' evidentiary threshold, operating outside the consent-based safeguards of the Data Protection Ordinance. Profiling restrictions, ADM transparency, AI-specific risk assessments, biometric regime, and genetic-data regime could not be confirmed from accessible sources.
no periodic updates on record for this sub-brief
Sources and claims (1)
UncertainarXiv — The Cyber Security Ordinance 2025 permits interception of, or access to, traffic data where authorities have 'reason to believe' that an offense has occurred, is occurring, or may occur, enabling investigative and preventative surveillance activities that operate outside the consent-based and rights-oriented mechanisms established by the Data Protection Ordinance.observed
No children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.
Traffic-light rationale — Not assessedNo children/vulnerable-groups-specific provisions located in this research pass; treated as a genuine coverage gap rather than silent omission.
Sub-modules (5)
Age VerificationRed
No confirmed age-of-consent or age-verification provision retrieved.
No age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adults protection could be confirmed for Bangladesh's data protection framework from accessible sources.
Supervisory authorityNational Data Governance and Interoperability Authority (NDGIA)
Traffic-light rationale — AmberRegulator identity and recent legislative developments confirmed; penalties, enforcement track record, funding, and redress mechanisms unconfirmed.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
NDGIA's enforcement/guidance role confirmed; specific maximum penalty amounts unconfirmed.
Claims (1):
The National Data Governance and Interoperability Authority (NDGIA) is designated as the body responsible for enforcing Bangladesh's data protection law(s) and issuing implementing guidelines.
Enforcement Activity IndexRed
No confirmed enforcement actions or decisions retrieved.
Within the past 180 days, the framework moved from presidential ordinance to full parliamentary enactment.
Claims (1):
Bangladesh's data protection framework progressed from presidential promulgation of the Personal Data Protection Ordinance to enactment by Parliament within the first half of 2026.
Category narrative57 words
The NDGIA is confirmed as the body responsible for enforcing the Data Protection Ordinance, 2025, and the framework's most significant recent development is its own legislative progression: presidential promulgation followed by parliamentary enactment within the past 180 days. Maximum penalties, enforcement-activity track record, regulator funding/capacity, collective-redress mechanisms, and private-right-of-action availability could not be confirmed from accessible sources.
no periodic updates on record for this sub-brief
Sources and claims (2)
UncertainDataGuidance — The National Data Governance and Interoperability Authority (NDGIA) is designated as the body responsible for enforcing Bangladesh's data protection law(s) and issuing implementing guidelines.observed
UncertainDataGuidance — Bangladesh's data protection framework progressed from presidential promulgation of the Personal Data Protection Ordinance to enactment by Parliament within the first half of 2026.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
5.26
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Bangladesh
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 10 claim(s) (10 category placement(s)), 22 source(s) in the cumulative register.
Two of ten modules (regulator_and_framework, controller_processor_duties) reached partial T2-sourced confirmation on their headline sub-modules (regulator identity, act/instrument history, breach notification). Two further modules (sectoral_watch, algorithmic_biometric_and_surveillance_governance) reached amber via a single T3 academic source confirming state-surveillance carve-outs (Cyber Security Ordinance 2025, Bangladesh Telecommunication Regulation Act). enforcement_and_redress reached amber on regulator identity and recent legislative developments only. The remaining sub-modules across all ten modules, and the entirety of cross_border_and_adequacy, adtech_and_commercial_privacy, and children_and_vulnerable_groups, carry no T1 (primary statutory text) coverage: the Data Protection Ordinance 2025's Bangla-language original text was not independently retrieved, and DataGuidance's detailed guidance notes were paywalled beyond headline/citation fragments. No T1 primary-source module achieved full coverage in this run.
Unresolved questions (7):
What is the precise commencement/effective date of the Data Protection Ordinance, 2025, and of any subsequent parliamentary Act superseding it?
Has the NDGIA issued subordinate rules/regulations covering DPIA triggers, DPO appointment thresholds, ROPA, or breach-notification timelines?
Does the Ordinance (or the related draft National Data Management Ordinance 2025) impose a data-localisation mandate, and does it specify cross-border transfer mechanisms (adequacy, SCCs, BCRs, derogations)?
What are the statutory maximum penalties for non-compliance under the Ordinance?
Has the NDGIA taken any confirmed enforcement action to date, and what is its funding/staffing capacity?
Does the Ordinance contain children/vulnerable-groups-specific provisions (age of consent, parental consent, minor profiling bans)?
What is the substantive content of Bangladesh Bank's financial-sector data-protection guidance referenced in paywalled secondary sources?